Impact
The vulnerability is an incorrect access control in the delSlaveDevice functionality of TOTOLINK T6 firmware 4.1.5cu.748_B20211015 that allows unauthenticated users to send a crafted MQTT message to the cs_broker component, causing the removal of a specified slave device from local mesh management data and rebooting the router. This can take devices offline and disrupt the local network.
Affected Systems
Affected systems are TOTOLINK T6 routers running firmware version 4.1.5cu.748_B20211015 or earlier that expose the cs_broker MQTT broker.
Risk and Exploitability
The flaw is exploitable without any authentication and requires only network access to the MQTT broker. EPSS score of < 1% indicates a low but nonzero exploitation probability. The CVSS score of 9.8 indicates critical severity. The vulnerability is not listed in the CISA KEV catalog, but the nature of the vulnerability—unauthenticated control of device removal and reboot—indicates it is a high‑risk, denial‑of‑service vector. Attackers could use any networked device capable of communicating with the cs_broker to trigger the exploit.
OpenCVE Enrichment